QID 317313

Date Published: 2023-03-27

QID 317313: Cisco Internetwork Operating System (IOS) XE Software Privilege Escalation Vulnerability (cisco-sa-iosxe-priv-esc-sABD8hcU)

QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.

An attacker could exploit this vulnerability by modifying the Meraki registration parameters. A successful exploit could allow the attacker to elevate privileges to root.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution

    Customers are advised to refer to cisco-sa-iosxe-priv-esc-sABD8hcU for more information.

    CVEs related to QID 317313

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-iosxe-priv-esc-sABD8hcU URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-priv-esc-sABD8hcU